it's an IIS website, and for SSO you can configure that with kerberos constrained delegation, and for a dual factor enable e.g. certificate based authentication on it.
If you can live without having SSO and need MFA to reach the director page you can create a simple but not perfect solution. It would be basically the same as Henry posted, missing the KCD/SSO part. So nothing has to be adjusted on the IIS or machine accounts delegation.
• Create a Load Balancer for the Director and configure this with AAA-preauth with SAML.
• Create a dedicated Enterprise Application for the director Web App (If you are using Azure) and enforce MFA by Conditional Access policy binding
Technically you have 1FA on the IIS after MFA pre-auth but inside SSL. So i am not sure if it might be sufficient. Kind of fake MFA 🙂
j
Jeremy Saunders
07/18/2023, 8:05 AM
Not sure how helpful this is, and I've never tried it myself, but got asked about implementing SAML2 authentication for my Self-Service Session Reset Tool. You could look at doing this at the IIS level using the Shibboleth ISAPI Filter, which is part of the Service Provider product and free for commercial use. There is plenty of helpful documentation on it.